All 5 CVE vulnerabilities found in Theme Editor, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2026-39640 | WordPress Theme Editor plugin <= 3.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution vulnerability CWE-352 | 8.3AI | HighAI | 2026-04-08 |
| CVE-2025-9890 | Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution CWE-352 | 8.8 | High | 2025-10-18 |
| CVE-2022-2440 | Theme Editor <= 2.8 - Authenticated (Admin+) PHAR Deserialization CWE-502 | 7.2 | High | 2024-08-29 |
| CVE-2023-6091 | WordPress Theme Editor plugin <= 2.7.1 - Arbitrary File Upload vulnerability CWE-434 | 7.2 | High | 2024-03-26 |
| CVE-2021-24154 | Theme Editor < 2.6 - Authenticated Arbitrary File Download CWE-552 | 4.9 | - | 2021-04-05 |
All 5 known CVE vulnerabilities affecting Theme Editor with full Chinese analysis, references, and POCs where available.